Title
Quantitative Assessment Of Software Vulnerabilities Based On Economic-Driven Security Metrics
Abstract
Vulnerability exploits cost organizations large amounts of resources, mainly due to disruption of ICT services, and thus loss of confidentiality, integrity and availability. As security managers in the industry usually have to operate with limited budgets allocated to information security, they need to prioritize their investment efforts regarding the response mechanisms to the existing vulnerabilities. The utilization of quantitative security vulnerability assessment methods enables efficient prioritization of security efforts and investments to mitigate the discovered vulnerabilities and thus an opportunity to lower expected losses. State of the art approaches for vulnerability assessment such as the Common Vulnerability Scoring System (CVSS), which is the de facto standard quantifying the severity of vulnerabilities, do not consider the economic impact in case of a vulnerability exploit. To this end, our paper targets the quantitative understanding of vulnerability severity taking into account the potential economic damage a successful vulnerability exploit can cause. We propose a novel approach for a systematic consideration of the relevant cost units (associated costs) for the economic damage estimation of vulnerability exploits. Our approach utilizes Multiple Criteria Decision Analysis (MCDA) methods to perform a prioritization of the existing vulnerabilities within the target system. The evaluation results show the potential cost savings w.r.t. the mitigation costs using our approach. Our method supports managers and decision makers in the process of prioritizing security investments to mitigate the discovered vulnerabilities.
Year
DOI
Venue
2013
10.1109/CRiSIS.2013.6766361
2013 INTERNATIONAL CONFERENCE ON RISKS AND SECURITY OF INTERNET AND SYSTEMS (CRISIS)
Keywords
Field
DocType
CVSS, economic-driven security metrics, MCDA, security quantification, vulnerability assessment
CVSS,Vulnerability (computing),Computer security,Computer science,Asset (computer security),Vulnerability assessment,Responsible disclosure,Vulnerability management,Secure coding,Vulnerability
Conference
ISSN
Citations 
PageRank 
2151-4763
2
0.41
References 
Authors
0
3
Name
Order
Citations
PageRank
Hamza Ghani1182.73
Jesus Luna214316.72
Neeraj Suri31040112.91